Free scan, no account

What has your team already put on the open internet?

Someone in operations built a tool in an afternoon, it worked, and people started using it. It is still running on a public address with the customer list inside. This scan finds those, using nothing but information that is already public.

No account. Nothing to install.

What the scan does

  • Searches public web results for apps published on the platforms below.
  • Looks up your public DNS records and certificate transparency logs for subdomains pointing at those platforms.
  • Reads your own public website for links to them.
  • Opens each candidate page once, the way any visitor would, and records the address, the page title and the platform fingerprint.

What it does not do

  • No logging in. The scan never enters a password, never uses a cookie or an API key, and never follows a redirect into a login page.
  • No probing. It does not guess file names, try admin paths, or look for a way in.
  • No content. Page text, screenshots and anything that looks like personal data are never stored.
  • No pressure to prove anything to see the numbers, and no addresses handed to anyone who has not proved they work at the company being scanned.

What you get

  • A summary at a private link straight away: how many apps were found and which platforms they are on, with the date each one first appeared.
  • If your address is at the domain you entered, a link to the full report goes to your mailbox: every address found, the risk score and the reasons written out. Opening that link is what proves the mailbox is yours.
  • Scanning a company you do not work at is fine. You see the summary, and you can send the full report to someone there. The addresses go to them, not to you.
  • Anything wrong gets one click to dismiss, so the list you keep is a list you trust.
  • Links work for 14 days. Findings from a scan without an account are deleted after 30 days.

Platforms the scan covers

The AI app builders

  • Lovablelovable.appApps built by describing them in chat, published on a lovable.app address.
  • Boltbolt.hostSame idea as Lovable, published on a bolt.host address.
  • Replitreplit.app, repl.coOlder accounts still sit on repl.co, newer ones on replit.app.
  • Base44base44.appInternal tools and simple databases, published on a base44.app address.
  • Emergentemergentagent.comNewer agent builder, added as it picks up traction.
  • Create.xyzcreated.appNewer agent builder, added as it picks up traction.
  • Rorkrork.appNewer agent builder, added as it picks up traction.

Where exported projects get deployed

  • Vercelvercel.app, v0.appWhere an exported Lovable or Bolt project usually ends up. Also catches v0 output.
  • Netlifynetlify.appThe other common home for an exported project.

The no-code layer that came before

  • Bubblebubbleapps.ioThe no-code layer that came before the AI builders. Plenty of it is still running.
  • Softrsoftr.appPortals and client dashboards built on top of a spreadsheet or Airtable base.
  • Glideglide.pageApps built from a spreadsheet, often shared on a public link.

Deliberately not scanned

Framer, Webflow, Squarespace, Carrd. Those build websites, not tools. Your marketing site being on a public address is the point of a marketing site, and reporting it as a risk would waste your time.